Meta’s Muse is an adorable privacy and security dumpster fire
techdirt.com
[126 comments hidden]
I just do not trust any of them, not with my money or with access to my conversations.
[6 comments hidden]
[5 comments hidden]
[hidden]
[2 comments hidden]
They also have a bad habit of accidentally building URLs that hit Alibaba infrastructure, likely because their training environment had them use those URLs. If you haven’t watched the outgoing network requests you might be very surprised at what your Qwen agents do sometimes.
[hidden]
It feels and seems too forced.
[5 comments hidden]
If Meta/OpenAI/etc would guarantee they’d compensate you in full for anything that wasn’t supposed to happen —and had an established track record of doing so— it would make trusting agents to make financial choices easier
[hidden]
lol… talk about delusion.
[hidden]
[hidden]
[hidden]
[66 comments hidden]
Unless these AI assistants are running on self-managed platforms independent of their developers, all I see is immense counterparty risk.
[10 comments hidden]
[9 comments hidden]
Notes: actual quote is "If you're evil, you're at least competent. And if you're evil, you're not bad. And therefore, maybe you're actually kind of good because you're at least getting something done"
[2 comments hidden]
[5 comments hidden]
[4 comments hidden]
[3 comments hidden]
> If you're evil, you're at least competent.
Incompetent evil exists. This statement is wrong, B does not follow A.
> And if you're evil, you're not bad.
They aren't mutually exclusive, so this is incorrect.
> And therefore, maybe you're actually kind of good because you're at least getting something done
This presupposes that "getting something done" is a positive end in itself, which is not a given.
Each phrase is wrong. It's impressive, actually.
[2 comments hidden]
both are evil but you can rationalise competent evil coz you're getting something real done like preventing the upending of the moral world order.
[hidden]
Considering weirdness of Thiel believes, his praise and support for actual atrocities, including actually in middle east, trying contrast him with violent religious fanatics is weird. They dont contrast, they have notable similarities.
[31 comments hidden]
Comments like this are in a different reality than most consumers. Most consumers don’t care about things like avoiding lock in to a platform. If the platform solves their problem then they don’t have any reason to leave it anyway. They’re not worried if their data is used to show them more targeted ads.
Topics like this show a sharp divergence between what you read on Hacker News and how actual users operate. We already knew that people who don’t trust Facebook aren’t going to suddenly start using Muse. They were never going to consider it. For the people who do actually use Meta products, which is a customer base counted in the billions, many will not have any problem using these tools.
[3 comments hidden]
[2 comments hidden]
[11 comments hidden]
[10 comments hidden]
[2 comments hidden]
[hidden]
Try as I might some are so addicted and gone now that they just come over, doom scroll for a few hours, and leave. Maybe they feel like they get something out of just being in the same room as other people. It confuses me, but I will not force my views on guests.
[7 comments hidden]
[6 comments hidden]
I even have a Talos workstation. Open hardware motherboard and open spec CPU both made in the US with fully open hardware. Also a Precursor which is similarly open.
I support these efforts as much as I financially can, but I admit open firmware/hardware is not a gap I have fully closed day to day. Yet. Deep down in some hardware is firmware I do not control, such as on the inside of my AMD GPUs. But I wallet-vote for those over Nvidia who require proprietary code in user space where it requires rights within my operating system.
[2 comments hidden]
How do you isolate those from affecting the rest of your machine? Do you use a different machine for entertainment? A different account? Something else?
I’m not judging or trying to catch you in some kind of gotcha, I’m interested in your setup in case the idea is something I could use myself.
[hidden]
[2 comments hidden]
[hidden]
Software Freedom means no one has more control of the hardware in front of you than you do. If no one can change the SSD firmware, then it is part of the hardware.
Now for firmware that can be changed, that is a different story and maybe the OpenSSD project gets us there. We will see.
[5 comments hidden]
These types of comments just show what a massive bubble you're in.
[3 comments hidden]
[hidden]
The fact you think it's a "clear majority" and not a "sizable, but still loud minority" of workers shows that you're in a bubble.
The vast, vast, majority of people are largely apathetic to AI as a technology at large, with general techbro-sentiment trending very negative (for all technology, across the board), especially towards SV/AI figureheads.
[hidden]
Or when they are hit by any other privacy fuckup like that.
[1] https://futurism.com/facebook-beauty-targeted-ads [2] https://www.bbc.com/news/health-61320202 [3] https://tech.yahoo.com/general/articles/facebook-made-money-...
[5 comments hidden]
But, “most consumers” don’t care about that. The beverage industry is insanely profitable, especially with recent forays into “energy drinks”.
Do people who drink so much dissolved sugar live without consequences? Absolutely not. They have a significantly lower quality of life and die much sooner than people who do not drink dissolved sugar.
I don’t see your comment as a valid dismissal. Just one more way that individual outcomes in our society are increasingly K-shaped.
[hidden]
[hidden]
- technologists : software that is bad for privacy
- nutritionists : food and drink that gives you diabetes
So, I'm no nutritionist, but I pay attention enough to pay attention when they say I shouldn't drink a liter of Coke every day. As technologists, we should carry the torch and speak loud-and-wide about the dangers of software that is bad for privacy.[hidden]
[hidden]
Doesn't that imply Meta itself believes users care?
[hidden]
[hidden]
Take smartphones. Don't want platform lock-in? Go fuck yourself. You're options are Apple and Google, who both maximize platform lock-in. You could always go live in the woods, that's freedom of choice baby. Welcome to the free market.
Of course, this is something you'll have to decide after reading the hundreds of pages of terms of use, privacy policies, and EULAs to learn how your data is actually being used. Oh, and they all update weekly. And you automatically consent.
The truth is that nobody trusts Facebook. It's a bargain. If you want to do certain things, you're forced to relinquish control. It doesn't matter if you trust them or not.
[20 comments hidden]
HN must understand that they are not a representative sample of anything.
[18 comments hidden]
It is reasonable to assume the majority of humans are intellectually lazy to the point of killing themselves and their families if told to with the right marketing.
We should all make our own individual well researched choices and not ever buy into the worthless argument of "everyone does it".
[17 comments hidden]
There are plenty of happy, successful people who didn't die because they used a Meta product.
In fact I'd even argue that all things equal, a Meta user is happier than a paranoid-meta-hater who worries every minute that someone is going to serve them an Ad that fits them
"oh, the horror!!!. How am I ever going to recover from the trauma and financial ruin of seeing a targeted ad."
[9 comments hidden]
Did you just move the goalposts to “it didn’t kill me”?
We’re talking about society-wide effects here, including harm to children for which Facebook is paying 17 billion dollars.
https://oag.dc.gov/release/attorney-general-schwalb-announce...
[6 comments hidden]
There is ZERO proven causality between social media usage (specifically Meta products) and long-term happiness of a person. All the social science are spurious correlations that can be attributed to anything (including higher education where hysteria about the modern world reins)
As far as $17B settlement, it has nothing to do with causality. It's just some $$$ set aside for Meta to remove operational headaches.
I could even say Meta-haters make more irrational life decisions compared to normal people who just browse Instagram and use WhatsApp without paranoia
[5 comments hidden]
[4 comments hidden]
[3 comments hidden]
[2 comments hidden]
[hidden]
I don’t have any vested interest in upholding those studies, for all I know you might be entirely right. But if they’re the only studies out right now, the onus is on you, as a minority dissenter, to say specifically why they’re wrong. To just handwave it away is to undercut your own position because it makes you look like a crank who is just casually attacking the state of the field. And in the context of a forum such as this, it’s very off-putting, obnoxious behavior.
You’d get no pushback if you actually substantiated your points rather than tossing around general criticisms.
[6 comments hidden]
And plenty of teens that never became happy and successful people because they used a Meta product.
These companies are predatory, and have nothing to offer us we cannot easily setup at home these days with privacy and sovereignty.
[5 comments hidden]
Note: Unless you spin an alternative universe there is no way you can prove causality of social media usage => happiness/depression.
[4 comments hidden]
But it is the undeniable opinion of most mental healthcare professionals that giving teens an endless stream of content about unattainable body images or suicide content... results in more suicides.
Meta -knew- this and then fired the team that told them about it and doubled down on pressing the gas. They knowingly and substantially increased the chances of teen suicides for money.
And people want to give these monsters -MORE- data and power? I cannot comprehend anyone defending this company still.
[3 comments hidden]
I mean some of the smartest people on HN fall for it, where is the hope for general masses?
[2 comments hidden]
Every time their stock price takes a hit my hope in humanity gets a little boost.
All proprietary technology will fail. I really wish it would fail faster though.
[hidden]
Well yeah that... and the spread of misinformation on Meta platforms leading to deaths from COVID. And the genocide in Myanmar they caused.
Information and outcomes are not separate. If you think the words you see, which are very carefully curated, truly have no effect on outcomes then you must have never attended a history class. Like, ever.
[hidden]
They were discussing how tesla manages problems with full-self-driving.
It was interesting how this realm of problems was viewed.
If there was an accident while the car was driving itself due to some glitch, the police at the scene put all the blame on the driver.
The book had a different viewpoint. obviously there was a tesla bug in full self driving, and they kept their mouth shut.
meanwhile society/government doesn't even think of this and puts responsibility/blame on the user.
[hidden]
We have a lot of deferred problems to go back and solve before all these dreams can come true.
[2 comments hidden]
[8 comments hidden]
[2 comments hidden]
Am I missing something with the concern about ability to constrain the blast radius?
[4 comments hidden]
[3 comments hidden]
[hidden]
[4 comments hidden]
"Hermes, clone this android app to my computer, add this and this feature and fix this annoyance and then rebuild it and push it to my phone"
"Hermes summarize this YouTube podcast and push the summary and transcript to my Obsidian vault"
"Hermes check mg obsidian notes for when I last wrote a blog article about Neovim's integration with AI agents"
*Hermes, you have an API token that allows read only access to the Zabbix monitoring system, check that and then use the Proxmox API token that only allows you to do limited actions to reboot the VM that is having issues"
Etc, etc,
[3 comments hidden]
[4 comments hidden]
I have no doubt they would have no problem outsourcing everything to agents.
[2 comments hidden]
Or did they make a fatally wrong diagnosis that was only discovered because the old doctor whipped out their medical encyclopedias? You left us hanging without the relevant part of the story!
[hidden]
You’re assuming you can get access to a qualified doctor in Europe, which isn’t always the case.
It was the same diagnosis my wife got from ChatGPT two weeks prior.
I think 90% of health issues are just hand-waved.
[6 comments hidden]
Last night I had ChatGPT go through an old email account and surface memories that I literally forgot. People who I have fond memories of. Yea I could have spent time querying gmail and digging but the agent did it in a way that really resonated. I don't care if Sama has my emails now. I do care about connecting with my past and enjoying the memories of a time long past.
Paranoid scolds of HN want the average person to be deprived of value like this for some reason.
[hidden]
[3 comments hidden]
I am perfectly prepared to believe you had a nice interaction with the robot. But this is an insane thing to say!
[2 comments hidden]
[hidden]
[hidden]
[2 comments hidden]
I find all this is just the next-gen privacy violation, disguised obviously as: "Oh, WOW an agent in the computer is doing all this for me". Bullshit.
It seems that never is enough with these ever thirsty companies, they keep pushing the limits and surprinsingly a lot of people do not care at all nor value the implications of having an arbitrary process running and doing pretty much whatever the agenda of their creators are.
[hidden]
I could see shopping being the same way, let the agent shop for you or identify good deals on things you want but then push them to you to make the actual purchase. Like you, I'm certainly not going to let an agent make a real purchase for me unattended and I doubt any merchant is going to have much sympathy for "my AI bought this by mistake".
[8 comments hidden]
[7 comments hidden]
I am very curious as to what other people of using these agents for? Some of the use cases I hear; comparative shopping, travel planning, etc. don't appeal to me. Our people using them to manage family life issues like school schedules, meetings, etc? I feel like I am missing out, but I also am not seeing the greater appeal yet.
[5 comments hidden]
Some of my recent use cases...
Help me find cheap flights and a hotel and plan some interesting sights to see because I am speaking at x conference on x date.
Download all my favorite music from x streaming service as FLAC files locally, then convert them to OGG and put them on my portable music player.
Download all my youtube subscriptions locally to this folder and strip out any ads or sponsored content.
Here are a list of all the books I own. Can you find me DRM-free epub copies and put them on this e-reader for me?
Here is a picture of an object next to a measuring tape. Can you 3d print me a holder perfectly sized for it based on a openscad file i can easily tweak?
I am really stressed right now. Can you help me talk through everything I have to do and help me rationally prioritize? Can you remind me and keep me on track and be my fake boss for today?
Can you look through my email and keep track of any appointments or invites so I stop missing meetings?
[2 comments hidden]
[hidden]
I mostly use jcode in part because of the self-dev mode where it edits its own rust code and restarts itself into new binaries seamlessly to give itself new features.
[2 comments hidden]
I'm wondering specifically about things like what kind of tool or restrictions you use on web browsing to avoid being flagged as a bot and how you guardrail access to your email (to avoid, say, the LLM deciding that "help me organize" includes telling people you want to reschedule). I use Qwen 3.8 26b at home and find it very useful for some tasks but when I think of using it as a general assistant rather than coding assistant, I keep thinking of times it has gone wildly wrong (e.g. it once spent 20 minutes trying to get around Supabase authentication because it couldn't figure why a certain call wasn't working)
[hidden]
That said for persistent things like interfacing with homeassistant etc I am playing with zeroclaw.
I run the same model as you for coding. For more sane automation tasks i recommend doing everything possible with MPCs so you can tell it to only use existing tools. ymmv
By no means is my setup well oiled yet. Different vms and systems doing different things. As a QubesOS user jailing an agent for one job to one VM is easy, though I am working on an enclave native operating system that should make this easier for most people.
[hidden]
I think as people realize that self-hosting is a good option. Good services will appear more
[3 comments hidden]
Speak for yourself. I hated the idea of agents ever since I first heard of it back in the 90s or 00s. For me, the most valuable feature of computers is predictability. I want tools, not agents. A computer should augment my own skills, not replace them.
[hidden]
[hidden]
> (…)
> I just do not trust any of them
So… Actually not the future stuff we wanted? That’s what bothers me when people say “we have the Star Trek computer”¹. We clearly don’t, because if we did we could trust it with a high degree of certainty. Instead what we have is a computer we must distrust to a high degree. One of the two crucial variables is flipped.
¹ I’m not saying you are saying that, but several people have expressed that sentiment on HN.
[hidden]
You can get it to do the price comparison part without having it do purchases.
I downloaded Muse, told it to find me some underwear to buy, asked some questions to narrow the options down, then once I came to a decision I went and purchased it myself.
[hidden]
[hidden]
[hidden]
I’m sure someone is going to lose their Robinhood account or savings but with due care this is avoidable.
[hidden]
I think for the former we can wait for bethel model, have better skills or give them small enough tasks. But for the latter, the only solution is honestly just hosting your own agent and all this having access to the data it creates, what it runs and what it reads.
[14 comments hidden]
[3 comments hidden]
[2 comments hidden]
[hidden]
[4 comments hidden]
This level of unfettered access to your personality, lifestyle, and secrets allows for an unprecedented kind of manipulation and control. You could see it as a new kind of wealth transfer: not only will They sell you things, They will subtly manipulate behaviors of the masses via trusted agents.
[3 comments hidden]
I think to the vast majority of people having one of these companies run an agent platform is going to be business as usual.
[hidden]
Here’s a prediction: the true AI moat will be owning the “AI friends” of the masses: a trusted coworker, therapist, personal music artist, or even just something to talk to. The moat comes from the fact that these “friends” will deeply understand the user and the users will want to “take them along” with their entire life (they’re useful!). So people will get “locked in” to their AI “team” which is only available via one of the major AI labs. And in turn, the AI labs parasitically will understand everything about the way you live and think at a level that traditional ad trackers could only dream of.
Sama has alluded to this in interviews for a long time. He stated a year ago [2]:
> The way that I think of it is that most people will want to have one AI service, and that needs to be useful to them across their whole life. And so you’ll use ChatGPT, but you’ll want it to be integrated with other services and so you need to have other apps inside of ChatGPT. We need to have an API business, because you will want to be able to sign in with OpenAI into some service that someone else has built, and you’ll want the kind of continuity of experience and you’ll want it to still know you and have your stuff and know what to share and what not to share. So we want to build this AI helper for people and that’s going to have to — there’s a few pieces that have to fit into that.
[1] https://www.nytimes.com/2012/02/19/magazine/shopping-habits....
[2] https://stratechery.com/2025/an-interview-with-openai-ceo-sa...
[hidden]
[hidden]
In mine, I don't.
That seems like an oversight/ opportunity.
[hidden]
Products like Facebook and Google search were magical in their early days, but over the past couple decades they have been relentlessly and deliberately degraded into useless slop.
The people who made all of those unfortunate decisions are the exact same people building and funding AI! What do you think they are going to do with more powerful Skinner boxes? Help the masses live their best, most empowered lives?!
[hidden]
[9 comments hidden]
[3 comments hidden]
I don't like or trust meta any more than I always did but I don't see how they could have done a "better" job with this. These kinds of agents are inherently pretty risky IMO but I don't see how this one is particularly more than any others.
Playing around with it I really don't get the sense there's any hidden prompt contradicting what's visible. It's nearly gleeful at using the VM in ways that were not intended and likely against meta's interests. I feel like someone must have won a really interesting internal power struggle to get this thing out in this form.
[2 comments hidden]
It will happily disclose its entire system prompt (which is interesting in its own right, and worth a read) or pop a reverse shell for you
> I don't see how they could have done a "better" job with this
I generally agree -- the openness is great. However, from experiences both inside and outside of Meta, good execution, a hacker ethic, and transparency ultimately has very little propping it up when money is on the line. In fact, it could be argued that Meta has a shareholder obligation to do profitable things such that even the best intentions can (and usually will) fall in the face of corporate hierarchy and sales numbers.
I think they did a pretty bang up job with Muse (the lack of communication with first-time agent users around how powerfully and confidently they can make horrifying mistakes, and how careful you need to be with prompting, and how even that sometimes isn't enough, notwithstanding).
I also think it will inevitably be used to squeeze profit, and given Meta's history, I think it's almost comical to not assume that will involve violations of the spirit of privacy. (and that's assuming that a proliferation of "it deleted all my files" "it messaged my ex" "it leaked private info" doesn't poison consumer sentiment before it even gets off the ground)
[5 comments hidden]
Also Meta is actively encouraging users to grant them full permission, insisting with all their marketing might that it’s safe, which they know is a complete lie. Hard to blame the user when they’re being actively deceived like this. Other agent companies are more reserved and say things like “be careful” but Meta is the opposite.
[2 comments hidden]
As for security models, it's probably long since time to sandbox all data and apps. More like mobile devices. Allow users to toggle that all off so they can use their computers for development etc, but the default state should force apps/tools to explicitly ask for permission to any folder, other app, API, CLI, etc. And ask for that permission regularly (or rather, reset the permission after some period of time). Or something like that (I haven't given it a great amount of thought).
[2 comments hidden]
[hidden]
[2 comments hidden]
What most people are arguing is whether or not it's worth it. These things are essentially executive assistants, which historically have also been massive vectors for security leaks. EAs know the most about you, your behaviors, and your motivations. Still an EA is almost always worth it if you can afford one. Given now the cost is free, Muse is something I've both used and recommended. It's worth the risk for me.
at the cost of all your data and probably your eternal soul
[hidden]
A free digital EA confers none of that—and it will annoy everyone you know. The only use case I see having legs is dealing with large bureaucracies like canceling subscriptions or medical billing issues, but there I think the common man will lose as the rise of this automation will see a distributed adversarial response from bureaucracies who will happily put up whatever barriers are needed to prevent Muse and other digital EAs from impacting their bottom line.
There's a 50/50 chance I'm just getting old here, but I really think we're going through an epochal shift where new consumer tech won't have the same reception as the smart phone and increasingly addictive bite-sized algorithmic media did over the last couple decades. I think going forward there will be more palpable questioning from younger generations about why do we even want some of these tech products? At some point convenience reaches diminishing returns and we have to think deeper about what we're trying to get out of life.
[hidden]
Call transcript with Guerra's Plumbing, Englewood, CO at September 17, 2026, 1:32 PM
Recipient: This is Robert.
Muse: Hi, this is Brett calling on Ankit Gordhandas’s behalf. I'll be transcribing this call for notes. I'm looking for a quote to install three customer-supplied bidet sprayers. Can you help with that?
Recipient: Can you soak my dick?
Muse: I'm just calling about the installation quote. Is there someone there who can help with plumbing pricing?
[hidden]
[2 comments hidden]
Trying to think of a number that I would consider it, and honestly $1k/month wouldn't convince me unless
- I have root on device
- device is on its own vlan, fully segmented
- !(SIM || 5G antenna)
- no google/apple id authenticated on device
- terminate agreement at any time without cost
I'm probably forgetting/not aware of ten things I should consider.
[5 comments hidden]
Why are we depending on LLM "reasoning" to negotiate a price rather than just having the user enter a lowest acceptable price deterministically?
[hidden]
[hidden]
[hidden]
(As a human, it's more physically taxing to think, and less taxing to relax. Conserving internal resources improves our survival odds. So when an opportunity presents itself to use less effort and still gain out of that, we tend to take it.)
As human technologists, I believe we need to protect humanity more.
In everything that we do, we need to think about the ways that our proclivities as a species can be compromised by our development of technology.
[2 comments hidden]
I don't trust any of the hyperscalers to place me as a user first, I expect them to guide me into a stall, strap on a feedbag, and start the value extraction process while they build the meatrix[1] around me.
I want tools like Muse, and Meta Glasses, Google Gemini and a horizontally integrated AI agent, but I want it on my terms, where I am in control and accountable, and without a layer of data collection and harvesting on top of it.
Fortunately I am skilled enough to assemble most of what I want, but I fear a world where people who lack the skills and resources I have available have no choice but to onboard and give up control in order to remain competitive, employed, and connected in the world to come :(
[hidden]
[2 comments hidden]
This is pretty funny! What ramp up? Building detailed profiles of you and your friends/etc is Meta's core business. They even build profiles for people who are not signed up for FaceBook, waiting/hoping for the day you join.
[5 comments hidden]
Can someone explain how this is possible? If an app can do this without Full Disk Access or a popup of some kind that's a way bigger lapse on Apple's part than Meta's.
[2 comments hidden]
Typical "leopards ate my face" moment. You give AI (from Meta, nonetheless) full-disk access and then complain that—wow—it really meant FULL.
In a perfect world where you got nothing to hide, where companies don't sell your data and there are no hackers, even I would love to just hand all my data to Muse and have it be my trusted assistant. People who think we live in such a world are already doing that, evidently.
[2 comments hidden]
[2 comments hidden]
[hidden]
[hidden]
We made a private SQL based Local Harness and LLM for your Mac M series. It sits in the middle between your data and the foundation models. Check out https://krystalize.ai and its privacy features.
[hidden]
The MOMENT they can, Meta will take all data they have about you and sell it to anyone who wants it, including to people who wish to do you harm.
Honestly, this is where actual government regulations with teeth would make me significantly more comfortable. But self-regulated? Absolutely not.
[3 comments hidden]
[2 comments hidden]
Whatever the reason, Claude (Code in terminal; my experience domain), despite explicit direction:
- "never leak any secrets" - "never display any passwords" - "everything to the right of the first '=' sign on any given line is a value; never echo or process it bare"
… etc.
--- 5 chats later ---
Notew hile working I accidentally echoed your Apple Keychain decrypted passwords. Oof sorry hehe"
[4 comments hidden]
Facebook is like Microsoft at this point: The thing your grandparents use.
Even if they make something technically superior for a while, like what the Zune was to the iPad, tHey'll never really be cool.
and they'll certainly never be trusted.
[3 comments hidden]
The Muse app is very polished and it seems to actually be popular with younger people.
I have tried it out but I’m still struggling with use cases, same problem I had with OpenClaw
[hidden]
[hidden]
[hidden]
Related:
Updates to Full Disk Access in macOS
https://news.ycombinator.com/item?id=49937631
Meta’s Muse has a serious 0-day
https://news.ycombinator.com/item?id=49802030
Unsurprisingly, Meta's new Muse AI agent blatantly ignores users permissions
https://news.ycombinator.com/item?id=49893709
Maybe don't let Muse run your Facebook Marketplace account
https://news.ycombinator.com/item?id=49875006
What Meta got right with Muse
https://news.ycombinator.com/item?id=49946526
Muse – Meta’s personal AI agent
[hidden]
[3 comments hidden]
[hidden]
That's their whole modus operandi, a privacy nightmare which will feed their infinite money machine.
Reading "Careless People" didn't make me surprised at all on how the company operates, it surprised me with the personal descriptions of how people like Mark Zuckerberg and Sherryl Sandberg actually are as humans. It scared me how most people at that level of wealth and power isn't too different from the accounts in the book, they're all seriously deranged people with a gigantic lever to impose their distorted realities upon the rest of humanity.
[hidden]
People who give their data to Meta are uncomfortable with Meta collecting that data.
Hmm.
[hidden]
[2 comments hidden]
[hidden]
[hidden]
No way I would allow them to develop the agent that runs my life. Even if it works well now, the rug pull is absolutely inevitable.
I was never all that into facebook, but it was nice to get an update on an old high-school friends once every month or two. Now its completely unviewable. Muse may be fun now, but it is one whim-of-Zuck from being unusable, or worse.
[2 comments hidden]
[hidden]
[7 comments hidden]
> Zuck: They "trust me"
> Zuck: Dumb fucks.
[6 comments hidden]
[hidden]
What lessons could zuck have learned, when he's been incredibly successful since these college days? The guy has become one of the richest and most powerful people on the planet _because_ of disregarding trust, and continues to operate the same way, I guess it's not impossible he fundamentally changed but I don't see a reason to think he did
[hidden]
Or it might just have been a dumb thing a young person said
[hidden]
Muse on the other hand is very much Your Agent and does not (yet) have silly limitations that work against your interests.
I hate Meta as much as the next guy, but Muse is well designed.
[2 comments hidden]
-Mark Zuckerberg
[4 comments hidden]
However, surely by now even the lay people who have seen the testimonies before Congress, the lawsuits and the excesses by Meta execs over and over again ought to be atleast somewhat wary of handing them more personal data?
I think the average person has very similar self preservation instincts as the rest of us. So it can't be that. Which leaves the fact that there are lot of people who don't know about the above mentioned scandals galore that Meta has been involved in?
[2 comments hidden]
I felt every agentic product was focusing on personal accounts. So I started building a platform for small teams and households (where you can have a personal workspace and a shared workspace). I am now testing it with friends and family, so if anyone wants an invite - join the list.
How it's different:
1) personal (private) and group context (e.g. household) 2) multiple guardrails 3) different architecture (not spinning up a VM for every user) while still protecting personal data 4) not run by Meta
piazzI’m pretty frustrated with Muse and the last thing I want to be doing with my free time is defending Meta, but this is such clickbait. Point[72 comments hidden]
Point by point:
> “OMG you can jailbreak it and get it to spill its VM”
This is the whole point; any content on the VM is yours. It runs in an isolated sandboxed VM separate from stored credentials etc; this is effectively your own computer. You don’t have to trick it.
> It collects dossiers on your contacts
These are more text files that live on your private VM, alongside memory.md, etc. Do you want your secretary to forget every person you contact every day?
> It accessed Messages without full disk access
This whole story never made sense or was substantiated. Full disk access is an OS level security boundary; the user had to switch this on.
> It sold some guys stuff for too cheap and gave out his address
OK this one I basically believe, haha. Because this is the problem with Muse: the LLM is just too dumb to perform complex tasks effectively in many cases.
ralphingtonYou just did the tech equivalent of "not to sound racist, but..."[hidden]
moscoeAbsolutely agree. So much feigned outrage in these articles (and HN comments) about the LLM models doing x. Yesterday everyone was all worke[7 comments hidden]
Yesterday everyone was all worked up about OpenAI generating an image with a signature on it.
Caveat emptor. Don’t be an idiot. Grow up. Make informed decisions regarding your use of these products and take responsibility for those decisions.
JohnMakin> Caveat emptor. Don’t be an idiot. Grow up. Make informed decisions regarding your use of these products and take responsibility for those [2 comments hidden]
Feigned outrage, indeed. I don't think it's unreasonable to point out that Meta has been consistently predatory, reckless, and creepy with user data before, and that this is a very aggressive expansion of that.
The old facebook booster retort of "if you don't like it, don't use it, take responsibility" or whatever is nonsense. You're in their system whether you use their product or not. Even if you somehow avoid their pervasive web-wide tracking, a single contact you know installing this thing and gobbling up all your correspondence with them can compromise your privacy choices, and that's well beyond your control, unless you seriously suggest I audit every single one of my contact's devices and browbeat them into using the privacy choices I prefer.
Get real.
bigyabai[hidden]
Why? I don't use Meta products, and my life isn't substantially impacted or controlled by them. Explain to me why I need to lobby my OS developers to reign-in Meta, from my perspective. Why is my hands-off approach insufficient for teaching adults to make intelligent decisions?
Facebook is unquestionably awful, but that's a regulatory issue. 90% of the people chiming-in with Facebook outrage aren't using Meta products; they are literally feigning surprise and outrage as someone that clearly knows better. Oftentimes, they oppose any regulation that would force Meta to reconcile their damages because it would also jeopardize other abusive monopolies like the App Store that they love to defend. So where does the buck actually stop? Does it ever?
HN has done this for years. Years and years and years. "Meta is horrible! Stop them!" -> "New Meta product has ~10-100 million MAU" -> "We need private enterprises to limit Meta!" -> Stagnant status-quo where exploitation is rewarded. Things got this bad because of the pugilist, tribal attitudes that dominated tech discussions and steered people away from common-sense regulatory measures.
stephen_cagleMy assumption is you clearly don't have vulnerable or elderly people in your life? I'm not as concerned about my ability to navigate these w[hidden]
slashdave> Make informed decisions regarding your use of these products They are mass marketed. The creators should do the upmost to ensure this and [hidden]
They are mass marketed. The creators should do the upmost to ensure this and not pin blame on users.
givinguflacIn this context, normal people will believe the marketing and trust meta, and caveat emptor is a cop-out at best. I can sell you a basket of[2 comments hidden]
bigyabai[hidden]
Take Meta out of the equation here; any agent with FDA can do the exact same thing. Claude, Codex, DeepSeek, any of them. This is why Apple's response is a fix to their own software. The fix is a mea-culpa, Apple would not have to patch their OS if it was behaving exactly the way they wanted it to. Apple and the journalist made the biggest mistakes here.
Meta is a godawful company that should be regulated into the dirt until Zuck is left with nothing. Guess what? They're not to blame in this scenario, and your rabid attacks on lapcat (who is a reputable and generally impartial macOS developer) is unnecessarily hostile towards a perfectly normal observation. This brand of comment is so misleading, low-effort and harmful to good-faith discussion that I'm tempted to flag this whole thread for being founded on a misunderstanding. Your response has contributed to the derailing of this conversation by tribalist "Apple vs Meta" pundits who are drowning out a well-known and respected expert that has technically-salient architectural details to share. HN cannot foster intellectual gratification under these conditions.
cmiles74I gotta' disagree on this one. Meta made claims that it was taking privacy seriously and it turns out, not so much. I do think they should b[33 comments hidden]
jonplackettAnyone who believes meta are taking privacy seriously cannot have more than a handful of brain cells.[2 comments hidden]
bdangubic[hidden]
IshKebab> it turns out, not so much Why though? The comment you're replying to is explaining how the accusations of poor privacy are nonsense and yo[hidden]
Why though? The comment you're replying to is explaining how the accusations of poor privacy are nonsense and you've just replied "I disagree because they have poor privacy".
I mean I'm not going to hand over any data to Facebook if I can help it but it doesn't seem like there are any specific issues here.
piazzOkay, but what is the evidence to back up this assertion? My point is, at this time, there is none. There is no “it turns out”. Give them so[26 comments hidden]
GeekyBear[21 comments hidden]
https://www.inc.com/jason-aten/metas-new-muse-ai-agent-read-...
lapcat[20 comments hidden]
The Messages database is protected by macOS TCC. If Aten were correct, there would exist a macOS zero day vulnerability.
The vastly more likely explanation is that Aten mindlessly gave Full Disk Access to Muse. And that appears to be Apple's assumption, based on Apple's newly published developer note.
cmiles74[5 comments hidden]
lapcat[hidden]
GeekyBear[2 comments hidden]
Meta's claim that Muse would not read your messages without explicit permission was meaningless.
judge2020[hidden]
But it was true and you still haven't refuted that Aten mindless clicked through and allowed Muse full disk access and/or the messages connector setting in the Muse app.
cloudfudge[hidden]
GeekyBear[13 comments hidden]
> Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with.
lapcat[12 comments hidden]
> > Some developers are using Full Disk Access in ways that could put users at risk
In other words, Muse did have Full Disk Access. Jason Aten did grant Full Disk Access to Muse, despite his claims otherwise.
If Aten did not grant Full Disk Access to Muse, then why would Apple even be talking about Full Disk Access?
The point is that Aten apparently granted Full Disk Access absent-mindedly, so absent-mindedly that he won't even admit that he did it. This is why Apple is making changes to Full Disk Access to make it more obvious what's happening.
GeekyBear[11 comments hidden]
Perhaps you should do some reading on the matter?
> Meta CTO David Singleton joined the fray with a rebuttal that appeared solid. For Muse to access Apple Messages, a user must manually give it two privileges. One is full-disk access, a macOS system-level permission. The other is to enable a Messages connector setting in Muse.
“The Messages integration in the Muse Mac app is opt in,” Singleton said. “Your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled.”
Singleton’s implication was clear. Muse could have read Aten’s Messages communications only if he had enabled both settings, and if so, the columnist had only himself—and certainly not Meta—to blame.
https://arstechnica.com/security/2026/10/apple-changes-full-...
Meta has a long history of not respecting boundaries once something is technically possible.
lapcat[8 comments hidden]
Perhaps you should: https://lapcatsoftware.com/articles/2026/10/2.html
> Singleton’s implication was clear. Muse could have read Aten’s Messages communications only if he had enabled both settings, and if so, the columnist had only himself—and certainly not Meta—to blame.
Indeed, and it looks like Aten absent-mindedly did all of this!
> Meta has a long history of not respecting boundaries once something is technically possible.
It's not technically possible for Muse to read the Messages db without Full Disk Access. Aten denies having given FDA to Muse. Thus, Aten is simply wrong, misremembering or something. And if he misremembers about FDA, he likely also misremembers about granting app-level permissions to Muse.
Again, literally nobody has reproduced Aten's experience. Show me one other person.
In fairness, Aten behaved just like many other users would, mindlessly granting permissions that an app requests. That's certainly a problem. Unfortunately, Aten stubbornly refuses to admit this, instead confusing the problem by suggesting technical impossibilities. Aten doesn't want to take any responsibility for his own actions.
GeekyBear[5 comments hidden]
Since Aten has clearly said he did not grant Muse the permission to read his messages (inside Muse), I'm not accepting your version of the events.
lapcat[4 comments hidden]
cloudfudge[3 comments hidden]
GeekyBear[2 comments hidden]
In this case, Meta explicitly promises that Muse will not read your messages even after you grant it disk permissions.
lapcat[hidden]
There's no reason to doubt this claim. The only person in the world who has claimed that Muse disrespects its own internal setting is the same person who claimed that he didn't grant Full Disk Access to Muse.
Ironically, Aten's own screenshot appears to show that he toggled the internal setting from "Off" to "Read only". In my own testing, it's "Off" by default, and the only way to change the internal setting is to enable Full Disk Access first.
Thus, the likeliest scenario is that Aten unthinkingly granted Full Disk Access to Muse, granted the Messages app permission, then had a change of heart, disabled Full Disk Access, and then forgot what he had done. Later, when he noticed that Muse had some of his messages, he went back and checked, and saw the FDA was disabled, forgetting that he had toggled it on and off.
givinguflac[2 comments hidden]
lapcat[hidden]
Moreover, my "opinionated" blog post also included a screen recording of the Muse first run experience, so everyone can see for themselves what it's like. And if you don't trust my screen recording, then you can perform the exact same experiment yourself. Nothing I did was unique.
b112[hidden]
ipsum2[hidden]
givinguflac[hidden]
runarberg[4 comments hidden]
When an actor has shown it self to be this malicious, we should be allowed to assume all the worst thing about it. And we should at the very least resist and complaint whenever it shows it self able to cause even more harm to humanity.
piazz[2 comments hidden]
Trump is stripping the White House for copper and selling it!! Well, actually he’s not, but since we know he’s corrupt, isn’t it safe to just assume he might also be doing this other bad thing?
If your decision is to avoid Muse due to Meta’s poor track record, that’s absolutely your prerogative (and a reasonable one!). But specific claims must be evaluated based on their evidence. This article fails that. There’s no story here.
runarberg[hidden]
Off course there is space between the worst and the best case. But given Meta’s history it is safest (and the most rational) to assume the worst.
mapremap[hidden]
moffkalastAh yes, Meta and privacy. Two things that go together like a jet engine and a library.[3 comments hidden]
redindian75[2 comments hidden]
moffkalast[hidden]
hitekkerIt's the market for attention. Many of techdirt's writers are heavy Bluesky users so most of their articles cater towards other Bluesky user[3 comments hidden]
JMiaoi started using bluesky recently and the venting seemed about normal by internet standards[2 comments hidden]
watwut[hidden]
GeekyBear> It accessed Messages without full disk access >This whole story never made sense or was substantiated This story makes perfect sense, and [22 comments hidden]
>This whole story never made sense or was substantiated
This story makes perfect sense, and Meta has a long history of not respecting user privacy controls.
> tech columnist Jason Aten said that Meta’s new general-purpose AI agent Muse sent him an unsolicited notification referencing a thread between him and a co-worker over Apple Messages. Aten said he never granted Muse permissions to read his messages and had assumed they were off-limits
https://arstechnica.com/security/2026/10/apple-changes-full-...
bigyabaiWhich privacy control did they fail to respect, in this instance? Everything on the journalist's machine was working as-intended.[hidden]
kccqzyThe reason that story didn’t make sense to me was that the tech columnist never showed the Apple system settings on whether full disk access[14 comments hidden]
First I doubt Muse is that good of an AI. Second, even if that’s the case, why wouldn’t someone report it to Apple to get thousands of dollars in bug bounty rewards?
GeekyBear[13 comments hidden]
> Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with.
kccqzy[12 comments hidden]
I’ll be charitable and say the user isn’t lying. Okay he has made a mistake in the initial granting of permissions. Then why didn’t he correct or retract the article?
GeekyBear[10 comments hidden]
One that the journalist in question did not turn on.
lapcat[8 comments hidden]
Muse cannot bypass built-in macOS protections. TCC does not work on "the honor system", any more than UNIX permissions. It doesn't matter how nefarious Meta happens to be. Operating system security is designed to be resistant to malware.
GeekyBear[7 comments hidden]
I'm just going to have to ignore you on this issue.
> Meta CTO David Singleton joined the fray with a rebuttal that appeared solid. For Muse to access Apple Messages, a user must manually give it two privileges.
bigyabai[hidden]
lapcat[5 comments hidden]
Sure, what do I know? After all, I'm only [checks notes] a 20 year veteran of Mac software development with multiple Apple-issued CVEs to my credit. ¯\_(ツ)_/¯
> > Meta CTO David Singleton joined the fray with a rebuttal that appeared solid. For Muse to access Apple Messages, a user must manually give it two privileges.
Yes. Those two:
1. Full Disk Access
2. The Messages Setting in Muse
As I said, without the first, the second alone won't allow Muse to read your Messages db. Do you not understand why Singleton said that Muse needs both?
GeekyBear[4 comments hidden]
Hence Apple's statement that the first permission was being abused to destroy any promises of user privacy.
lapcat[3 comments hidden]
The problem here is that Aten claimed he did not grant the first, and moreover, you have been defending that claim of Aten's in these comments.
As soon as you admit that Aten did indeed grant the one permission, it's not much of a stretch to conclude that he also granted the second permission. It would be very odd, I think, to distrust Aten in the one case yet stubbornly take him at his word in the second.
Again, if even one other person in the entire world could reproduce Aten's alleged experience...
GeekyBear[2 comments hidden]
Meta promised that they would not read a user's messages without an additional permission the user must enable inside of Muse, even after they granted Muse full disk access.
A journalist reported that Muse read his messages despite the fact that he did not grant permission for it to do so inside Muse. He never claimed he did not grant full disk access.
Apple announced that the full disk access permission was being abused.
lapcat[hidden]
False. In fact he has claimed this multiple times:
"Full disk access off. Muse synced 187k lines form my messages chat db." https://www.threads.com/@jasonaten/post/DdezsMJFhBr
"I still haven’t gotten an answer as to how it was reading my messages with Full Disk Access turned off, but I’d be happy to dig into it with anyone from Meta that wants to help." https://www.inc.com/jason-aten/meta-keeps-apologizing-for-mu...
This is why he's not a reliable narrator.
And another false claim he made, "Also, that full disk access doesn’t say anything about your message database", which anyone can easily refute by opening System Settings and reading the text.
cma[hidden]
TeMPOraL[hidden]
There is no answer to that consistent with the premise you assumed out of charity :).
lapcat> Meta has a long history of not respecting user privacy controls. Meta's respect is irrelevant, because macOS TCC prevents any and every ap[5 comments hidden]
Meta's respect is irrelevant, because macOS TCC prevents any and every app, including malware, from accessing your Messages database without Full Disk Access.
> he never granted Muse permissions to read his messages
That's what he said, but I would suggest that one person's memory is a lot more fallible than a longstanding operating system security feature.
givinguflac[4 comments hidden]
How on earth, after literally decades of abusive behavior by meta, are you standing the straw man that maybe and based on your assumption the user is lying??
lapcat[3 comments hidden]
I said that Aten is misremembering. That's not the same as lying. We all misremember things.
I don't care about or trust Meta. In my blog post about the Muse first run experience, I said, "For testing I used a fresh VM, not signed in to my Apple Account, because of course I don’t trust Meta with any of my data!" https://lapcatsoftware.com/articles/2026/10/2.html
What I do care about is truth and accuracy. My mistrust of Meta is not going to make me distort the truth. Muse cannot bypass macOS TCC, that's a simple truth.
I'm a macOS software developer. That's the reason for my interest in this story, the technical aspects of it.
littlebuddy[2 comments hidden]
lapcat[hidden]
No. What you're missing here is that Muse for Mac is a native, compiled, code signed, notarized app, with specified entitlements. It can't simply rewrite its own executable code, so it can't do whatever it wants. You can even reverse engineer the app. Muse looks in ~/Library/Messages for the messages database; this is actually hard-coded in the executable file. Whatever ideas the remote LLM may come up with cannot automatically be translated into instructions that are executed by the Mac app. That's not how it works.
zardoAren't permissions on notifications less restricted then full disk access?[hidden]
butlike> I’m pretty frustrated with Muse and the last thing I want to be doing with my free time is defending Meta Then don't.[hidden]
Then don't.
iAMkenoughNice! Starting my own crypto miner using Meta infra then.[hidden]
al_borlandIn. Jonna Stern’s interview with Zuckerberg he talked about the security, and how they delayed it to make sure they got it right. He then we[hidden]
I felt like he was undermining his original point. They delayed to make it better, but didn’t delay long enough to do the actual right thing he mentioned they could potentially do in the future.
When it’s pulling in data from all over the phone or computer, it’s not just the user’s data. Some of my personal data (detailed contact info, emails, etc) can be pulled in and used by Muse if someone I know installs it, without my knowledge or consent. That needs to be taken seriously, and Meta has a history of abusing this concept (uploading fully address books to find friends)
greenavocado> the LLM is just too dumb to perform complex tasks effectively in many cases. Muse Spark 1.3 is way better than anything else out there out[hidden]
Muse Spark 1.3 is way better than anything else out there outside of the US labs except Deepseek Flash which comes close.
yaloginUsing an encrypted VM is standard but the encryption is the core issue. Just plain encryption will allow them to proclaim it’s all secure/pr[hidden]
I don’t trust meta will do any of this